mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-08 04:11:18 +02:00
test: replace product tests that fake the product with real-boundary tests (F)
- design: serve.test.ts drove an inline mirror server; now two tests run the real serve() on an ephemeral port (reload confinement, submit exit 0). - setup-gbrain: rollback + voyage tests execute the template-extracted init blocks (3 sites) instead of drifted local bash copies. - terminal-agent: internalHandler source greps replaced by a behavioral /internal/grant + /internal/revoke auth matrix (no/wrong/valid token). - /health: server-security-surface and the server-auth / security-audit-r2 / sidebar-tabs source greps fold into one liveness-only check on the real body; the L4 sidecar wiring gets a behavioral /pty-inject-scan test. - delete tautologies (browser-manager onDisconnect, memory-command #12), ios swiftui tap fixture self-check, memory-ingest put_page grep, detach source greps, sidebar-agent absence pins, dead-CSS pins + the dead CSS, security-audit-r2 Task 1 + the test-only meta-commands re-export, duplicate generated-SKILL.md checks. - make-pdf coverage-gaps cases move into their owner test files.
This commit is contained in:
1 parent
6dc624eda6
commit
5ec930d569
33 files changed
+638
-1830
No files matched your search
@@ -115,6 +115,50 @@ describe('terminal-agent: /internal/grant', () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe('terminal-agent: /internal/grant and /internal/revoke bearer auth', () => {
|
||||
function post(route: 'grant' | 'revoke', token: string, authorization?: string): Promise<Response> {
|
||||
const headers: Record<string, string> = { 'Content-Type': 'application/json' };
|
||||
if (authorization !== undefined) headers.Authorization = authorization;
|
||||
return fetch(`http://127.0.0.1:${agentPort}/internal/${route}`, {
|
||||
method: 'POST',
|
||||
headers,
|
||||
body: JSON.stringify({ token }),
|
||||
});
|
||||
}
|
||||
|
||||
function wsStatus(token: string): Promise<number> {
|
||||
return fetch(`http://127.0.0.1:${agentPort}/ws`, {
|
||||
headers: { 'Origin': 'chrome-extension://abc123', 'Cookie': `gstack_pty=${token}` },
|
||||
}).then((r) => r.status);
|
||||
}
|
||||
|
||||
for (const route of ['grant', 'revoke'] as const) {
|
||||
test(`${route}: no token → 403, wrong token → 403, valid internal token → 200`, async () => {
|
||||
const target = `auth-matrix-${route}-token-long-enough`;
|
||||
expect((await post(route, target)).status).toBe(403);
|
||||
expect((await post(route, target, 'Bearer wrong-token')).status).toBe(403);
|
||||
expect((await post(route, target, `Bearer ${internalToken}`)).status).toBe(200);
|
||||
});
|
||||
}
|
||||
|
||||
test('an unauthenticated revoke leaves the grant usable; an authenticated revoke removes it', async () => {
|
||||
const token = 'revoke-auth-token-at-least-seventeen';
|
||||
expect((await grantToken(token)).status).toBe(200);
|
||||
expect(await wsStatus(token)).not.toBe(401);
|
||||
expect((await post('revoke', token)).status).toBe(403);
|
||||
expect((await post('revoke', token, 'Bearer wrong-token')).status).toBe(403);
|
||||
expect(await wsStatus(token)).not.toBe(401);
|
||||
expect((await post('revoke', token, `Bearer ${internalToken}`)).status).toBe(200);
|
||||
expect(await wsStatus(token)).toBe(401);
|
||||
});
|
||||
|
||||
test('an unauthenticated grant does not register the token', async () => {
|
||||
const token = 'forged-grant-token-at-least-seventeen';
|
||||
expect((await post('grant', token, 'Bearer wrong-token')).status).toBe(403);
|
||||
expect(await wsStatus(token)).toBe(401);
|
||||
});
|
||||
});
|
||||
|
||||
describe('terminal-agent: /ws gates', () => {
|
||||
test('rejects upgrade attempts without an extension Origin', async () => {
|
||||
const resp = await fetch(`http://127.0.0.1:${agentPort}/ws`);
|
||||
|
||||
Reference in new issue
Block a user